Torva security scanning

Know what your scan covers.

See exactly what Torva Edge and Core check, what remains unassessed, and how to interpret findings and regulatory references.

Torva performs bounded technical checks. A high score means the checks performed found fewer issues; it does not establish that a network is secure or an organization is compliant.

Edge: your verified public domains

Core: your approved internal ranges

Not currently checked

Authenticated operating-system patch inventory, CVE-database matching, Active Directory posture, SMB signing, broad UDP/SNMP discovery, full web application testing and organization-wide MFA enforcement are not included. Core does not currently scan IPv6 ranges. IP-based TLS observations do not provide full hostname/SNI coverage. Sleeping, filtered or unreachable devices may remain unassessed.

Regulatory and framework references

Select HIPAA, tax-preparation safeguards context or NIST CSF 2.0. A technical finding can relate to several cited references, but it is counted once in a unique-finding total. Applicability and supporting evidence still require review. NIST CSF is a framework, not a regulation. Source checks flag changes for review; they do not automatically approve revised legal interpretations.

Read a representative report · Compare plans

Create an account Ask for a walkthrough